First published: Tue Mar 09 2021(Updated: )
There is a race condition in OozieSharelibCLI in Apache Oozie before version 5.2.1 which allows a malicious attacker to replace the files in Oozie's sharelib during it's creation.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Oozie | <5.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35451 has been classified with a medium severity that allows attackers to manipulate Oozie's sharelib.
To fix CVE-2020-35451, upgrade to Apache Oozie version 5.2.1 or later.
CVE-2020-35451 is a race condition vulnerability affecting the OozieSharelibCLI in Apache Oozie.
All versions of Apache Oozie before 5.2.1 are affected by CVE-2020-35451.
Yes, CVE-2020-35451 can be exploited remotely by a malicious attacker.